I am hosting multiple services, but my application/web security knowledge is lacking. Is there a guide or framework to check for common or risky mistakes? Is there a list of things I should check every application for, or guide on how to harden hosted applications? That is a topic that I am going to tackle in the near future, and would appreciate some tips in advance.
Thank you Jerry!
Not yet. Just got access to the test clients and I have planned to do a troubleshooting session tomorrow in the morning. Not a big fan of stress testing the network on a working day haha
Will do. I'll updated the original post most likely and ping you. I've added a per-IP traffic shaper to limit the bandwidth, so this one user won't be able to slow down the location and I am about to prepare the troubleshooting session on the weekend.
Not sure on the logging. I’m a data center guy and would rather see firewalls in the trash lol. They usually just cause problems.
Haha - I'd like to disagree, but you are right.
For the WAN, surely there is some way you can reach those sites over the general internet. You have ISP connections.
I for sure could do it, but it is not that easy to expose a server to the internet. There would be multiple departments involved and I need to get permission. And yeah, even with IP whitelisting. I guess that will be my last resort.
Still waiting for the test clients. Probably going to shift some hours into the weekend so I don't disturb daily business.
No worries, thank you for your input!
- what logging/debugging would you activate for that case? - Not too familiar with Fortigate yet and would appreciate some tipps, IF you are familiar with those.
- the IPSec tunnel is the only connection between these locations so it is rather difficult. But I get what you mean and check if there is another option.
Good points!
I'll keep that in mind
You are right. Still an active policy that we have to work on.
Could be, for sure. I could disable the security profile for some tests and check if it happens with it turned off. Good points, thank you.
I am certain that we block ICMP on multiple FW in between. I could allow it temporary and check. Good suggestion.
Will compare it as soon as I get my hands on the machine.
And yeah, we do tend to block ICMP over here too.
Thank you!